Kaspersky Lab Open-Sources its Threat-Hunting Tool

'KLara' was built to speed up and automate the process of identifying malware samples.

Kaspersky Lab is now offering its homegrown threat-hunting application KLara as an open-source tool, the company said today.

KLara is a YARA rules-based malware scanner that runs multiple YARA identifier rules across multiple databases simultaneously as a way to speed up the process of malware identification. Kaspersky Lab said it created the tool as a distributed system for YARA searches that includes researchers' own malware collections as well as others.

"Detecting cyberthreats requires tools and systems that can hunt effectively for malware – particularly when tracking advanced targeted threat campaigns through months or even years of activity," said Dan Demeter, security researcher at Kaspersky Lab and one the creators of KLara. "We created KLara to help us hunt threats better and faster" and are now sharing it with the security community, he said.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.

An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy i...